Handala (MOIS / Banished Kitten)
Iranian state-sponsored (MOIS — Ministry of Intelligence and Security) · Politically motivated disruption / hack-and-leak / psychological operations against Israel and Western interests
Tactics, Techniques & Procedures (TTPs)
- Hack-and-leak operations against Israeli government, military, and private sector organisations
- Wiper malware deployment for destructive impact against Israeli targets
- Third-party SaaS platform exploitation for lateral access to adjacent operational or billing systems
- Exaggerated OT compromise claims for psychological/influence operations (capability claims systematically overstated)
- Data publication via Telegram and dedicated leak sites for maximum public pressure
- US and Western critical infrastructure targeting as retaliation for US-Iran military engagement (from February 2026)
- GNSS and positioning platform exploitation as entry point to utility-adjacent systems
Known Targets
Analyst Notes
Handala has been active since December 2023, named after a Palestinian cartoon character and explicitly framing operations as retaliation for Israeli and US actions. The June 2026 Cal Water breach — via internet-facing RTKBase GNSS positioning platform — exfiltrated 5GB of customer PII across seven operational districts. Mandiant's investigation found no evidence of access to OT or water treatment systems. Handala's claim to have capability to 'shut off water' was assessed as unsupported for influence purposes. Operations scaled significantly following US military engagement against Iranian targets from February 2026. MOIS-attributed via Banished Kitten tracking cluster.
Also Known As